Back to skill

Security audit

Kaomoji Spirit

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight kaomoji style helper that can change chat tone but does not request code execution, credentials, files, network access, or privileged actions.

Install this if you want an assistant that can add kaomoji automatically in casual or emotional chats. Avoid enabling it where neutral, formal, technical, legal, medical, financial, or emergency responses must stay completely plain, and verify the minor version mismatch if strict release provenance matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill defines very broad automatic activation conditions based on common emotional words, greetings, and short conversational phrases, which can cause it to trigger during ordinary user interactions without an explicit invocation boundary. This creates prompt-scope interference risk: the assistant may alter tone, inject stylistic output, or divert responses in contexts where accuracy, neutrality, or restraint are more important.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal